Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2560▼ 348 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | Oscommerce CE PhoenixAI | 11/12/2025 | 1/10/2026 | CE Phoenix v3.0.1 contains a stored cross-site scripting vulnerability in the currencies administration panel that allows attackers to inject malicious scripts. Attackers can insert XSS payloads in the title field to execute arbitrary JavaScript when administrators view the currencies page. | |
| Analizada | Crítica (9) | 0.25% | — | Phoenixcart CE Phoenix Cart | 2/6/2025 | 17/6/2026 | CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial description field. Once submitted, if the shop owner (admin) approves the… | |
| Aplazada | Media (5.5) | 0.16% | — | CE Phoenix Ecommerce PlatformAI | 2/6/2025 | 17/6/2026 | The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public machine) could permanently delete the… | |
| Aplazada | Media (4.8) | 0.81% | — | Oscommerce CE PhoenixAI | 12/3/2024 | 17/6/2026 | HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component. | |
| Analizada | Alta (7.2) | 27% | — | Phoenixcart CE Phoenix Cart | 16/2/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php. | |
| Modificada | Media (6.1) | 0.96% | — | Oscommerce CE Phoenix | 3/9/2020 | 17/6/2026 | Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php,… |